REVIEWS.io for WooCommerce Security & Risk Analysis

wordpress.org/plugins/reviewscouk-for-woocommerce

REVIEWS.io, helps eCommerce merchants to collect & display verified product and company reviews. A Google Licensed partner.

1K active installs v1.5.5 PHP 7.4+ WP + Updated Sep 18, 2025
company-reviewsgoogle-reviewsreviewsseller-ratingsstars-in-adwords
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 10, 2024
Safety Verdict

Is REVIEWS.io for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

REVIEWS.io for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 10, 2024Updated 6mo ago
Risk Assessment

The reviewscouk-for-woocommerce plugin v1.5.5 exhibits a generally good security posture based on the static analysis. The complete absence of unprotected entry points, including AJAX handlers and REST API routes, is a significant strength. The plugin also demonstrates robust coding practices with 100% of SQL queries using prepared statements and a very high percentage of output escaping. The presence of nonce and capability checks, even if limited in number, further contributes to its secure design.

However, the static analysis does not cover all potential attack vectors, and the taint analysis results are listed as 0 flows analyzed, indicating that deeper, dynamic analysis might not have been performed or did not uncover specific unsanitized paths. While the vulnerability history shows only one past medium-severity vulnerability (Cross-site Scripting) and no currently unpatched issues, it is important to note that the last reported vulnerability was very recent, suggesting that ongoing vigilance is necessary. The presence of a past XSS vulnerability, even if patched, warrants attention for any unescaped outputs or potential input handling flaws that might be missed by static analysis alone.

In conclusion, the plugin has implemented several key security best practices. The absence of critical vulnerabilities and the strong adherence to prepared statements and output escaping are commendable. The primary area for potential concern lies in the limited scope of the taint analysis and the recent history of a medium-severity vulnerability. While the current version appears secure based on the provided data, the plugin's developer should continue to prioritize thorough security testing and rapid patching of any newly discovered issues.

Key Concerns

  • Past medium severity vulnerability (XSS)
  • Taint analysis not performed or yielded 0 flows
Vulnerabilities
1

REVIEWS.io for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-38677medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REVIEWS.io <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 10, 2024 Patched in 1.2.9 (21d)
Code Analysis
Analyzed Mar 16, 2026

REVIEWS.io for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
234 escaped
Nonce Checks
2
Capability Checks
2
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

97% escaped241 total outputs
Attack Surface

REVIEWS.io for WooCommerce Attack Surface

Entry Points9
Unprotected0

Shortcodes 9

[product_reviews_widget] woocommerce-reviews.php:1931
[rating_snippet] woocommerce-reviews.php:1932
[richsnippet] woocommerce-reviews.php:1933
[nuggets_widget] woocommerce-reviews.php:1934
[nuggets_bar_widget] woocommerce-reviews.php:1935
[ugc_widget] woocommerce-reviews.php:1936
[rating_bar_widget] woocommerce-reviews.php:1937
[carousel_widget] woocommerce-reviews.php:1938
[survey_widget] woocommerce-reviews.php:1939
WordPress Hooks 35
actionadmin_enqueue_scriptsincludes\settings-page.php:2073
actionbefore_woocommerce_initwoocommerce-reviews.php:36
actionadmin_initwoocommerce-reviews.php:93
actionadmin_menuwoocommerce-reviews.php:94
filterinitwoocommerce-reviews.php:95
actionhourly_order_process_eventwoocommerce-reviews.php:96
filterwpseo_schema_productwoocommerce-reviews.php:101
actioninitwoocommerce-reviews.php:106
actionreviewsio_process_product_feed_eventwoocommerce-reviews.php:107
filterscript_loader_tagwoocommerce-reviews.php:557
actionwp_footerwoocommerce-reviews.php:1073
actionwp_footerwoocommerce-reviews.php:1330
actionwp_footerwoocommerce-reviews.php:1540
actionwp_footerwoocommerce-reviews.php:1575
actionwp_footerwoocommerce-reviews.php:1799
actionwoocommerce_order_status_completedwoocommerce-reviews.php:1850
actionwoocommerce_after_shop_loop_itemwoocommerce-reviews.php:1855
actionwoocommerce_single_product_summarywoocommerce-reviews.php:1857
actionwp_footerwoocommerce-reviews.php:1860
actionwp_footerwoocommerce-reviews.php:1864
actionwp_headwoocommerce-reviews.php:1868
actionwp_footerwoocommerce-reviews.php:1870
actionwp_footerwoocommerce-reviews.php:1882
actionstorefront_before_footerwoocommerce-reviews.php:1888
actionelementor/elements/categories_registeredwoocommerce-reviews.php:1892
actionelementor/widgets/registerwoocommerce-reviews.php:1893
actionelementor/widgets/registerwoocommerce-reviews.php:1895
actionadmin_enqueue_scriptswoocommerce-reviews.php:1905
filtertemplate_redirectwoocommerce-reviews.php:1911
filterwoocommerce_product_tabswoocommerce-reviews.php:1914
filterwoocommerce_after_single_productwoocommerce-reviews.php:1917
filterwoocommerce_after_single_product_summarywoocommerce-reviews.php:1919
filterwoocommerce_single_product_summarywoocommerce-reviews.php:1922
filterwp_footerwoocommerce-reviews.php:1925
actionwp_footerwoocommerce-reviews.php:2014

Scheduled Events 2

reviewsio_process_product_feed_event
hourly_order_process_event
Maintenance & Trust

REVIEWS.io for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 18, 2025
PHP min version7.4
Downloads58K

Community Trust

Rating60/100
Number of ratings2
Active installs1K
Developer Profile

REVIEWS.io for WooCommerce Developer Profile

reviewscouk

1 plugin · 1K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
21 days
View full developer profile
Detection Fingerprints

How We Detect REVIEWS.io for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reviewscouk-for-woocommerce/css/admin-style.css/wp-content/plugins/reviewscouk-for-woocommerce/js/admin-script.js/wp-content/plugins/reviewscouk-for-woocommerce/js/widget-options-script.js
Script Paths
https://cdn.jsdelivr.net/npm/@simonwep/pickr/dist/pickr.min.js
Version Parameters
reviewscouk-for-woocommerce/css/admin-style.css?ver=reviewscouk-for-woocommerce/js/admin-script.js?ver=reviewscouk-for-woocommerce/js/widget-options-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
reviewsio-widget-containerreviewsio-product-widget
Data Attributes
data-reviewsio-store-iddata-reviewsio-product-id
JS Globals
reviewsio_data
Shortcode Output
[reviewsio_product_rich_snippet][reviewsio_reviews_widget][reviewsio_nuggets_widget][reviewsio_nuggets_bar_widget]
FAQ

Frequently Asked Questions about REVIEWS.io for WooCommerce